Sr. Product Security Engineer

Trane Technologies•Minneapolis, MN
•Hybrid

About The Position

Thermo King is hiring an experienced Senior Product Security Engineer to work on the creation and implementation of secure embedded software by demonstrating a comprehensive understanding of secure by design principles to support the next-generation transport refrigeration and mobile HVAC controls platform while meeting vehicle cybersecurity and software-update regulatory type-approval requirements. In this role, you will lead the cross-product efforts to regularly assess threats and vulnerabilities, perform Security DFMEA, and review penetration tests & threat modeling reports on products throughout its lifecycle. You will use the findings from new threats to improve processes and productivity by providing guidance and implementing priority updates based on findings. Your tasks include developing and capturing requirements, coordinating implementation, and helping the team to deliver product security goals. You will work closely with Systems, Hardware, Software, and teams to understand customer needs, align product security with overall practices, and define effective product security solutions and oversee their development.

Requirements

  • Bachelor's or Master's degree in computer engineering, computer science, electrical engineering or related technical field with 5+ years of experience.
  • Experience with embedded software development and proficiency in relevant programming languages (e.g., C, C++, C#, Rust, Python).
  • Demonstrated expertise in securing embedded controls platforms, with hands-on knowledge of Embedded Linux (e.g., Yocto) and RTOS environments (e.g., FreeRTOS, Zephyr Project, MicroC/OS-II).
  • Working knowledge of secure boot, hardware root of trust and secure elements, PKI, code signing, and key management for embedded systems.
  • Strong grasp of static analysis (SAST) and software composition analysis techniques for vulnerability detection and remediation.
  • Familiarity with modern DevOps pipelines and tools (e.g., GitHub Actions, Azure DevOps, GIT), with practical knowledge of automated testing frameworks (e.g., CppUTest, Pluma).
  • Effective communicator with strong organizational skills, adept at working with cross-functional teams and presenting technical risks to varied audiences.
  • Commitment to ongoing learning and driving continuous maturity in product security processes and technical strategies.

Nice To Haves

  • Experience as an embedded product security engineer.
  • Experience with automotive or vehicle cybersecurity and regulatory type approval (ISO/SAE 21434, UNECE R155/R156) and secure over-the-air software updates is strongly preferred.
  • Preferred background securing in-vehicle and telematics networks—CAN J1939/CAN FD with SecOC, Automotive Ethernet/SPE (100Base-T1, 10Base-T1S) with MACsec and TLS 1.3, and MQTT with mutual TLS.
  • Familiarity with ISO/SAE 21434 TARA, UNECE R155 and R156, ISO 24089, and/or GB 44495-2024 type-approval expectations.

Responsibilities

  • Assess product security risks in a maintained register, develop comprehensive mitigation strategies, and evaluate technical and business trade-offs.
  • Apply the Secure Development Lifecycle and lead product security processes including architectural analysis, threat modeling, security DFMEA, penetration testing, attack modeling and simulation, cybersecurity type-approval activities including TARA per ISO/SAE 21434, and data privacy impact assessments.
  • Identify, evaluate, and verify security issues discovered through automated testing, penetration testing, and customer feedback. Maintain and track closure of vulnerability backlogs.
  • Interpret and enforce product security requirements, conduct vulnerability reviews, and ensure compliance with automotive and industrial cybersecurity regulations and standards (UNECE R155, UNECE R156, ISO/SAE 21434, ISO 24089, GB 44495-2024, IEC 62443, NIST, and applicable regional data-privacy laws).
  • Support vehicle cybersecurity and software-update type approval by maintaining Cyber Security Management System (CSMS) and Software Update Management System (SUMS) processes and evidence aligned to regulations and standards.
  • Define and validate secure over-the-air and service-tool update paths, covering secure boot, hardware root of trust, PKI and certificate management, code signing, and anti-rollback protection across the zonal architecture and independent modules.
  • Apply privacy-by-design and support data-protection impact assessments to meet regional obligations such as GDPR, CCPA, LGPD, the EU Data Act, and California SB-327.
  • Monitor outputs and effectiveness from all security tools integrated within the software development lifecycle.
  • Advise, guide, and mentor cross-disciplinary engineering teams during the design, review, and implementation of security features.
  • Validate that software meets all functional, security, regulatory (cybersecurity compliance), and quality benchmarks particularly within industrial and transportation environments.

Benefits

  • Health insurance
  • Holistic wellness programs
  • Fertility coverage
  • Adoption/surrogacy assistance
  • Up to 15 vacation days
  • Paid holidays
  • Sick leave
  • Additional options to support volunteer and parental leave
  • 401K match
  • Educational and training opportunities
  • Tuition assistance
  • Student debt support
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service